Code Execution Risk in Penpot Open-Source Design Tool
CVE-2026-105691

9.9CRITICAL

Key Information:

Vendor

Penpot

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-105691?

Penpot, an open-source design and prototyping platform, contains a vulnerability in its SVG exporter that allows an attacker to exploit the fill-color attribute of text objects. Prior to version 2.18.0, this exporter executes a command string that can be controlled by an attacker using shell metacharacters. Users with file editing permissions can therefore trigger this vulnerability by modifying the fill color and exploiting the SVG export process. Furthermore, this malicious behavior could be executed through a valid public share link pointing to a maliciously crafted file. The issue has been remediated in version 2.18.0.

Affected Version(s)

penpot < 2.18.0

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.